Field notes on offensive security, application and API testing, and building software that stands up to attack.
Most private equity firms treat cyber diligence as a checkbox in the pre-close workstream — a questionnaire, a policy review,...
A traditional network penetration test asks a simple question: what can I reach, and what can I do once I get there? That question...
Ask a security team how many APIs their company runs and you will usually get a number. Ask engineering the same question and you...
For twenty years, phishing defense leaned on a quiet assumption: the attacker would make a mistake you could see. Bad grammar, a...
Your identity program probably has a good story for humans. People get onboarded, assigned roles, reviewed quarterly, and...
Encryption buys you time, not permanence. That distinction rarely matters, because most stolen data loses its value long before...
Most of the code running in your production environment was not written by your team. A typical service pulls in a handful of...
The annual penetration test is a ritual most engineering organizations inherited without examining. Once a year, a team arrives,...
For the last few years, the security conversation around large language models has been about what the model says. Can it be...